Travel Fans
Go Back   Computer Juice Computer Software Virus, Spyware & Security

Register

 Default 

DNSChanger!d Trojan Detected: Can't Remove :( Please Help!




Reply
 
Thread Tools
  #11  
Old 20th May 2009, 21:57
New Member
Posts: 10
 
I was about to do the last step, but my McAfee just detected the trojan again :(

Ughhhh. Any ideas?? I'm sorry it didn't get rid of everything.

  #12  
Old 21st May 2009, 09:16
Moderator
Posts: 7,552
 
This scanner works with Internet Explorer only!

Scan with the BitDefender Online Scanner
Click I Agree to the license and then install the ActiveX control.
Please DO NOT change the Scanning Options.
That will make your logs huge and we don't need to see clean files.

Select Start Scan to begin.
This scan can take a while so please be patient and let it complete.

Once BitDefender completes the scan:
Click-on the Detected Problems tab.
Then select Click here to export the scan report



This will save a file named bdscan.html I would suggest saving it to the Desktop so you can easily find it. (take notice of where you save it so you can find it later)

You will have to upload the file online. The forums will not accept HTML.

Go to File Dropper

Click Upload
Locate the file and double click it.
Copy the link below Share This Link: and post it back here.
__________________

  #13  
Old 21st May 2009, 14:59
New Member
Posts: 10
 
Here is the saved file.

http://www.filedropper.com/virus

This is after McAfee located the trojan and "deleted" it. I haven't restarted my pc since then, fyi.
  #14  
Old 21st May 2009, 15:09
Moderator
Posts: 7,552
 
Looks good.

Use the Secunia Software Inspector to check for out of date software.
Out of date software has security vulnerabilities that malware can exploit.
  • Click Start Now
  • Check the box next to Enable thorough system inspection.
  • Click Start
  • Allow the scan to finish and scroll down to see if any updates are needed.
  • Update anything listed.


----------

Go to Microsoft Windows Update and get all critical updates.

----------

Make sure all of your security programs are up to date and run scans with them regularly.

I suggest using WOT - Web of Trust. WOT is a free Internet security addon for your browser. It will keep you safe from online scams, identity theft, spyware, spam, viruses and unreliable shopping sites. WOT warns you before you interact with a risky website. It's easy and it's free.

SpywareBlaster - Secure your Internet Explorer to make it harder for these ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox.
* Using SpywareBlaster to protect your computer from Spyware and Malware
* If you don't know what ActiveX controls are, see here

Check out Keeping Yourself safe On The Web for tips and free tools to keep you safe in the future.

Also see Slow Computer? It May Not Be Malware for free cleaning/maintenance tools to help keep your computer running smooth.
__________________

  #15  
Old 21st May 2009, 21:27
New Member
Posts: 10
 
I did what was suggested. When I use Google to search something, and click on a link, it sends me to random website :( I fear I am still infected.
  #16  
Old 21st May 2009, 21:45
Moderator
Posts: 7,552
 
Are you using Firefox?

Download GooredFix from one of the locations below and save it to your Desktop.

Link #1
Link #2

* Double-click GooredFix.exe to run it.
* Select 1. Find Goored (no fix) by typing 1 and pressing Enter.
* A log will open, please post the contents of that log in your next reply (it can also be found on your desktop, called GooredLog.txt).

Note: Do not run Option #2 yet.
__________________

  #17  
Old 21st May 2009, 21:49
New Member
Posts: 10
 
Yes I am. Although recently I've been using IE8 (Joke, since Firefox has been the browser acting up. Sorry, it's late =p)

Here is the log.

GooredFix v1.92 by jpshortstuff
Log created at 00:48 on 22/05/2009 running Option #1 (Administrator)
Firefox version 2.0.0.20 (en-US)
=====Suspect Goored Entries=====
C:\Program Files\Mozilla Firefox\extensions\{A25706AF-2B31-4BDF-AC9D-3E0B34717C4A}
=====Dumping Registry Values=====
[HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\Mozilla Firefox 2.0.0.20\extensions]
"Plugins"="C:\Program Files\Mozilla Firefox\plugins"
[HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\Mozilla Firefox 2.0.0.20\extensions]
"Components"="C:\Program Files\Mozilla Firefox\components"
[HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\Firefox\extensions]
"jqs@sun.com"="C:\Program Files\Java\jre6\lib\deploy\jqs\ff"
[HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\Firefox\extensions]
"{20a82645-c095-46ed-80e3-08825760534b}"="C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\"
  #18  
Old 22nd May 2009, 07:51
Moderator
Posts: 7,552
 
Double click GooredFix.exe on your Desktop to run it.

* Select 2. Fix Goored by typing 2 and pressing Enter. Make sure all instances of Firefox are closed at this point.
* Type y at the prompt and press Enter.
* A log will open.
* Please post the contents of that log in your next reply (it can also be found on your desktop, called GooredLog.txt).

Note: If you receive a message saying that GooredFix needs your system to be restarted, please close all applications and reboot your system. Please also allow any registry changes that may be prompted by any of your security programs.

Are you still getting the redirects?
__________________

  #19  
Old 22nd May 2009, 08:00
New Member
Posts: 10
 
GooredFix v1.92 by jpshortstuff
Log created at 10:58 on 22/05/2009 running Option #2 (Administrator)
Firefox version 2.0.0.20 (en-US)
=====Goored Deletions=====
C:\Program Files\Mozilla Firefox\extensions\{A25706AF-2B31-4BDF-AC9D-3E0B34717C4A}
->Backing up folder... Done.
->Emptying folder... Done.
->Deleting folder... Done.
=====Dumping Registry Values=====
[HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\Mozilla Firefox 2.0.0.20\extensions]
"Plugins"="C:\Program Files\Mozilla Firefox\plugins"
[HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\Mozilla Firefox 2.0.0.20\extensions]
"Components"="C:\Program Files\Mozilla Firefox\components"
[HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\Firefox\extensions]
"jqs@sun.com"="C:\Program Files\Java\jre6\lib\deploy\jqs\ff"
[HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\Firefox\extensions]
"{20a82645-c095-46ed-80e3-08825760534b}"="C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\"

So far no redirects! Thank you VERY much EF, you are a blessing to us all.
  #20  
Old 22nd May 2009, 09:02
Moderator
Posts: 7,552
 
Glad it worked.

Click Start > Run and then copy/paste the following into the box and then click OK
Code:
"%userprofile%\Desktop\GooredFix.exe" /uninstall
If any of your security programs query a new Registry/AutoStart value being added please allow the changes.
__________________

Reply

Register

Similar Threads
Thread Thread Starter Forum Replies Last Post
Trojan.DNSchanger Wont Delete on Reboot with MBAM or SUPERantispyware nor Combofix Annapelle Virus, Spyware & Security 10 20th Jul 2009 18:05
HDD sometimes cannot be detected by the Motherboard lauz006 Drives & Removable Media 2 15th Jun 2009 02:37
Bluetooth not detected? Haun General Hardware Chat 6 31st Dec 2008 11:47
Please help! Can't remove Trojan.Vundo.H amit1234 Virus, Spyware & Security 43 20th Dec 2008 20:38
Trojan.vundo.h , trojan.agent , adware.mirar + MORE! :( sillyarfer Virus, Spyware & Security 1 14th Dec 2008 09:59
Thread Tools



Translations Powered by Powered by Google
Arabic Bulgarian Chinese Croatian Czech Danish Dutch English Finnish French German Greek Hebrew Hungarian Italian Japanese Korean Latvian Lithuanian Norwegian Polish Portuguese Romanian Russian Serbian Slovak Spanish Swedish Taiwanese Thai Turkish Ukrainian

Copyright ©2006 - 2010 Computer Juice.

Powered by vBulletin® Copyright ©2000 - 2010 Jelsoft Enterprises Ltd. SEO by vBSEO ©2009, Crawlability, Inc.